statamic/cms Security Advisories for v3.4.15 (2)
-
[HIGH] Statmic CMS vulnerable to account takeover via XSS and password reset link
PKSA-8pw7-xndm-5j7f CVE-2024-24570 GHSA-vqxq-hvxw-9mv9
Affected version: <3.4.17|>=4.00,<4.46.0
Reported by:
GitHub -
[MEDIUM] Statamic's Antlers sanitizer cannot effectively sanitize malicious SVG
PKSA-gfgd-dxd9-46qj CVE-2023-36828 GHSA-6r5g-cq4q-327g
Affected version: <4.10.0
Reported by:
GitHub